Junglewise Threat Intelligence

CVE-2026-83463: Oracle Mobile Application Server auth bypass in MWA Terminal Server

CVE-2026-83463 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Mobile Application Server. Vendors: Oracle.

Executive brief

Oracle Mobile Application Server is a core component of Oracle E-Business Suite that handles mobile application traffic and terminal server communications. An unauthenticated attacker with physical access to the network segment where the server resides can exploit a difficult-to-exploit vulnerability to take complete control of the server, potentially compromising sensitive business data and disrupting operations across the entire E-Business Suite environment.

Technical details

The vulnerability exists in the MWA Terminal Server component of Oracle Mobile Application Server and allows unauthenticated remote code execution or system compromise. The attack requires adjacent network access (physical proximity to the communication segment) but no authentication credentials or user interaction, making it accessible to network-adjacent attackers. The difficulty of exploitation is elevated by unspecified complexity factors (AC:H), but successful exploitation results in complete system takeover with high impact to confidentiality, integrity, and availability. The vulnerability affects versions 12.2.3 through 12.2.15 of Oracle E-Business Suite's Mobile Application Server.

Affected products

  • Oracle Mobile Application Server 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats